PT-2006-4705 · Mospray · Mospray

Kurdish Security

·

Published

2006-07-25

·

Updated

2018-10-17

·

CVE-2006-3847

CVSS v2.0

5.1

Medium

VectorAV:N/AC:H/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions MoSpray (aka com mospray) version 1.8 RC1
Description The issue allows remote attackers to execute arbitrary PHP code via a URL in the basedir parameter in multiple PHP files, including admin.php, details.php, modify.php, newgroup.php, newtask.php, and rss.php.
Recommendations For MoSpray (aka com mospray) version 1.8 RC1, consider restricting access to the basedir parameter in the affected PHP files until a patch is available. As a temporary workaround, avoid using the basedir parameter in the affected files to minimize the risk of exploitation.

Exploit

Fix

Code Injection

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2006-3847

Affected Products

Mospray